瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 瑞星注册表监控频繁出现提示如何解决?

1   1  /  1  页   跳转

瑞星注册表监控频繁出现提示如何解决?

瑞星注册表监控频繁出现提示如何解决?

每次一打开IE,瑞星注册表监控频繁出现提示
注册表项HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT WORD\SHELL\EDIT
HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT WORD\SHELL
HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT WORD
发现 删除<默认>
进程名称 C:\Program Files\Internet Explorer\iexplore.exe

另外瑞星也不允许自动长级,说下载升级必需文件失败.请您换其它时间段尝试,但是我地同公司的其他机则可以,请问

这个问题如何解决呢?谢谢!


最后编辑2006-07-25 20:15:30
分享到:
gototop
 


这是我机子目前运行的日志,麻烦高手帮忙看一下.

2006-07-25,18:32:28

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 非管理权限用户 - 受限功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMJPMIG8.1)("C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [Microsoft Corporation]
(PHIME2002ASync)(C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [Microsoft Corporation]
(PHIME2002A)(C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [Microsoft Corporation]
(IgfxTray)(C:\WINDOWS\system32\igfxtray.exe) [Intel Corporation]
(HotKeysCmds)(C:\WINDOWS\system32\hkcmd.exe) [Intel Corporation]
(PRONoMgr.exe)(C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe) [Intel(R) Corporation]
(RavTask)("C:\Program Files\Rising\Rav\RavTask.exe" -system) [Beijing Rising Technology Co., Ltd.]
(RfwMain)("C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup) [Beijing Rising Technology Co., Ltd.]
(Acrobat Assistant 7.0)("C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe") []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
(BaiduInstall)(C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\baidu\bar\BDBAR_~1\BaiduBar.dll,Install) [Baidu.com, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
({32CD708B-60A7-4C00-9377-D73EAA495F0F})(C:\WINDOWS\system32\RavExt.dll) [Beijing Rising Technology Co., Ltd.]




--------------------------------------------------------------------------------


启动文件夹

服务

[Intel NCS NetService / NetSvc]
(C:\Program Files\Intel\NCS\Sync\NetSvc.exe)(Intel(R) Corporation)
[Rising Proxy Service / RfwProxySrv]
(c:\program files\rising\rfw\rfwproxy.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Personal Firewall Service / RfwService]
(c:\program files\rising\rfw\rfwsrv.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Process Communication Center / RsCCenter]
("C:\Program Files\Rising\Rav\CCenter.exe")(Beijing Rising Technology Co., Ltd.)
[RsRavMon Service / RsRavMon]
("C:\Program Files\Rising\Rav\Ravmond.exe")(Beijing Rising Technology Co., Ltd.)



--------------------------------------------------------------------------------



浏览器加载项

[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, )
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} (C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.)
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} (C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation)
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} (C:\Program Files\Messenger\msmsgs.exe, N/A)
[百度超级搜霸]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} (C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.)
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (C:\WINDOWS\system32\CMBEdit.dll, )
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (C:\WINDOWS\system32\muweb.dll, Microsoft Corporation)
[Submit Class]
{A3CD7F74-93C9-4BC4-B892-CCDF1514F714} (C:\WINDOWS\Downloaded Program Files\safein.dll, Beijing eChannels Century Technology Co.,Ltd)
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, )
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (C:\WINDOWS\system32\CMBEdit.dll, )
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} (%SystemRoot%\system32\mshtml.dll, N/A)
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} (C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation)
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} (C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (C:\WINDOWS\system32\muweb.dll, Microsoft Corporation)
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} (C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.)
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation)
[Tool Class]
{A7F05EE4-0426-454F-8013-C41E3596E9E9} (C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.)
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} (C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[百度超级搜霸]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} (C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.)
[Adobe Acrobat Control for ActiveX]
{CA8A9780-280D-11CF-A24D-444553540000} (C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated)
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash.ocx, Macromedia, Inc.)
[上传到QQ网络硬盘]
(D:\yoyo\d\文件夹\Adobe\Tencent\QQ\AddToNetDisk.htm, N/A)
[导出到 Microsoft Excel(&x)]
(res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A)
[添加到QQ自定义面板]
(D:\yoyo\d\文件夹\Adobe\Tencent\QQ\AddPanel.htm, N/A)
[添加到QQ表情]
(D:\yoyo\d\文件夹\Adobe\Tencent\QQ\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(D:\yoyo\d\文件夹\Adobe\Tencent\QQ\SendMMS.htm, N/A)
[百度--MP3搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM, N/A)
[百度--图片搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM, N/A)
[百度--新闻搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM, N/A)
[百度--歌词搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM, N/A)
[百度--网页搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM, N/A)
[百度--词典搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM, N/A)
[百度--贴吧搜索]
(RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM, N/A)
gototop
 

正在运行的进程

[PID: 2924][C:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\Program Files\WinRAR\rarext.dll] (N/A)(N/A)
[C:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 13)
[C:\PROGRA~1\baidu\bar\baidubar.dll] (Baidu.com, Inc.)(2, 0, 2, 78)
[C:\WINDOWS\system32\igfxpph.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\hccutils.DLL] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxres.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxsrvc.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxdev.dll] (Intel Corporation)(3.0.0.3929)
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] ()(1, 0, 0, 1)
[PID: 3368][C:\WINDOWS\system32\igfxtray.exe] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\hccutils.DLL] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxdev.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxsrvc.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxres.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxress.dll] (Intel Corporation)(3.0.0.3929)
[PID: 2580][C:\WINDOWS\system32\hkcmd.exe] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\hccutils.DLL] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxdev.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxsrvc.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxhk.dll] (Intel Corporation)(3.0.0.3929)
[C:\WINDOWS\system32\igfxres.dll] (Intel Corporation)(3.0.0.3929)
[PID: 1652][c:\program files\rising\rfw\RfwMain.exe] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 51)
[c:\program files\rising\rfw\RsGuiLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 23)
[c:\program files\rising\rfw\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[c:\program files\rising\rfw\PngDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[PID: 3916][C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe] (Intel(R) Corporation)(6.2.35.0)
[C:\Program Files\Intel\NCS\PROSet\CHSPGUIR.dll] (Intel(R) Corporation)(6.2.35.0)
[C:\Program Files\Intel\NCS\PROSet\8023\PNC802_3.dll] (Intel(R) Corporation)(6.2.35.0)
[C:\Program Files\Intel\NCS\PROSet\8023\CHSPCMRs.dll] (Intel(R) Corporation)(6.2.35.0)
[PID: 2904][C:\Program Files\Rising\Rav\RavTask.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 22)
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[C:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[C:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[PID: 2268][C:\WINDOWS\system32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 3860][C:\Program Files\Rising\Rav\Ravmon.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 10)
[C:\Program Files\Rising\Rav\RsGuiLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 23)
[C:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 16)
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[C:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[C:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[C:\Program Files\Rising\Rav\PngDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[PID: 1936][C:\WINDOWS\system32\wscntfy.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 2104][C:\Program Files\Internet Explorer\IEXPLORE.EXE] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\PROGRA~1\baidu\bar\baidubar.dll] (Baidu.com, Inc.)(2, 0, 2, 78)
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] ()(1, 0, 0, 1)
[C:\WINDOWS\system32\JPWB.IME] (常诚研制)(4.00.950)
[C:\Program Files\Rising\Rav\RavScrCh.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[C:\WINDOWS\system32\Macromed\Flash\Flash.ocx] (Macromedia, Inc.)(6,0,84,0)
[PID: 2764][C:\Program Files\Internet Explorer\iexplore.exe] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\PROGRA~1\baidu\bar\baidubar.dll] (Baidu.com, Inc.)(2, 0, 2, 78)
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] ()(1, 0, 0, 1)
[C:\Program Files\Rising\Rav\RavScrCh.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[C:\WINDOWS\system32\Macromed\Flash\Flash.ocx] (Macromedia, Inc.)(6,0,84,0)
[C:\PROGRA~1\baidu\bar\BDBar_tmp\BaiduBar.dll] (Baidu.com, Inc.)(2, 0, 2, 97)
[C:\WINDOWS\system32\JPWB.IME] (常诚研制)(4.00.950)
[PID: 3020][C:\Documents and Settings\YoYo\桌面\sreng2\SREng2\SREng.exe] (Smallfrogs Studio)(2.0.21.505)



--------------------------------------------------------------------------------



文件关联

.TXT Error. [Notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT